Homonymous role in role-based discretionary access control

Citation data:

Wireless Communications and Mobile Computing, ISSN: 1530-8669, Vol: 9, Issue: 9, Page: 1287-1300

Publication Year:
2009
Usage 565
Abstract Views 321
Full Text Views 240
Link-outs 4
Captures 29
Exports-Saves 22
Readers 7
Citations 1
Citation Indexes 1
Repository URL:
https://repository.hkbu.edu.hk/hkbu_staff_publication/1125; http://ir.lib.ncku.edu.tw/handle/987654321/87881
DOI:
10.1002/wcm.700
Author(s):
Chu, Xiaowen; Ouyang, Kai; Chen, Hsiao-Hwa; Liu, Jiangchuan; Jiang, Yixin
Publisher(s):
Wiley-Blackwell; Wiley
Tags:
Computer Science; Engineering; Discretionary access control; Homonymous role; Role based access control; discretionary access control; role based access control; homonymous role
article description
The access control model is a core aspect of trusted information systems. Based on the role based access control (RBAC) model, we put forward the concept of the homonymous role, which extends the role control categories in RBAC, balances the control granularity and the storage space requirements, and executes the fine-grained access control. Instead of the traditional global access control policies (GACP), we propose the homonymous control domain (HCD) mechanism to enable the coexistence of multiple types of access control policies in a single system, thereby improving the control granularity and flexibility. The HCD mechanism facilitates the discretionary supporting of independent access control policies for its homonymous user. The HCD mechanism and the traditional access control mechanism can be linked to construct a two-layer access control policy mechanism for a system. Notably, we also consider the temporal characteristic in HCD, which is a critical feature of modern access control models. Furthermore, we analyze the conflicts between the HCD and GACP mechanisms. Finally, we design and implement our HCD on FreeBSD to demonstrate the advantages of the two-layer access control mechanism. © 2008 John Wiley & Sons, Ltd.